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From application.xml 

<module id="WebModule_r> 

<web> 

<web-iiri>PBSecFVTServletLwar</web-uri> 
<context-root>/secfvt/ servlets/basicauth</ context-root> 
</web> 
</module> 

<module id- 'EjbModule_4"> 

<ejb>SecFVTS4EJB.jar</ejb> 

<alt-dd></alt-dd> 
</module> 

<security-role id= f, SecurityRole_l "> 

<description>Manager in an enterprise</description> 

<role-name>Manager</role-name> 
</security-role> 



Figure 5 - Excerpt From An Exemplary 

Application Deployment Descriptor 
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From web.xml 

<security-constraint id= M SecurityConstraint_l "> 

<web-resource-collection id- 1 WebResourceCollection_l "> 

<web-resource-name>Protected Area</web-resource-name> 

<url-pattern>/SecF VTS ervlet 1 / * </url-pattern> 

<http-method>DELETE</http-method> 

<http-method>GET</http-method> 

<http-method>POST</http-method> 

<http-method>PUT</http-method> 
</web-resource-collection> 
<auth-constraint id= M AuthConstraint_l "> 

<role-name>Manager</role-name> 

<role-name>Employee</ role-name> 
</auth-constraint> 
</ security-constraint> 



Figure 6 - Excerpt From An Exemplary 
Deployment Descriptor For A 
Web Module 
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From an ejb-jar.xml: 

<method-permission id= n MethodPermission_l "> 

<description> Allow All Authenticated users to create 

SecF VTS 1 EJB</description> 
<role-name>AHAuthenticated</role-name> 
<method id-"MethodElement_l n > 

<ejb«name>SecFVTS lEJB</ejb-name> 
<method-intf>Home</method-int£> 
<method-name>create</method-name> 
<method-params> 

<method-param>j ava. lang. String</method-param> 
</method-params> 
</method> 
</method-permission> 

<enterprise-beans> 

<session id="Session_r> 

<description>Security FVT Stateful Session Bean Test 

# 1 </ description> 
<display-name>SecFVTS 1 E JB</display-name> 
<small-icon></small-icon> 
<large-icon></large-icon> 
<ejb-name>SecFVTSlEJB</ejb-name> 
<home>com.ibm.ws. secfvtj ars.ejb. SecF VTS 1 Home</home> 
<remote>com.ibm.ws.secfvt.jars.ejb.SecFVTS 1 </remote> 
<ejb-class>com.ibm.ws.secfvt.jars.ejb.SecFVTSlEJB</ejb-class> 
<session-type>Stateful</session-type> 
<transaction-type>Bean</transaction-type> 
<security-role-ref id- 'SecurityRoleRef_l "> 

<description>Used for principal verification</description> 

<role-name>Emp</role-name> 

<role-link>Employee</role-link> 
</security-role-ref> 

<security-role-ref id- 'SecurityRoleRef_2"> 

<description>Used for principal verification</description> 
<role-name>Mgr</role-name> 
<role-link>Manager</role-link> 
</security-role-ref> 
</session> 
</enterprise-beans> 

Figure 7 - Excerpt From An Exemplary 
Deployment Descriptor For An 
EJB Module 



